Rorschach ransomware disrupts Chilean telecom operator Grupo GTD
- Organization
- Grupo GTD
- Exploit
- Ransomware
- Industry
- Telecommunications
Grupo GTD, a Chilean telecommunications and IT services group with operations in Chile, Peru, Colombia and Spain, was hit by a ransomware attack on the morning of Monday, October 23, 2023. The intrusion struck the company's Infrastructure as a Service platform, the layer it uses to host systems for corporate and public sector clients.
Chile's national computer security incident response team, CSIRT, identified the malware as Rorschach, also tracked as BabLock, a fast encryptor first documented in April 2023 that abuses DLL side loading in legitimate signed executables to run its payload. Disruption spread across GTD data centre services, internet access, IP telephony and VoIP, VPN connectivity and the group's over-the-top television platform. Several Chilean public sector websites that depend on GTD infrastructure went offline.
GTD disconnected the affected platform from the internet to stop the encryption spreading and notified CSIRT, which published four indicators of compromise so other organizations could check their own environments. It then restored services in stages.
ESET reported that more than 3,000 client organizations in Chile and Peru were affected, including systems tied to the national health fund FONASA and a records platform used by more than 77 municipal and regional governments. By early November, according to the same account, several hundred clients were still awaiting full restoration.